[{"content":"This might sound like clickbait or just another post about Security+, and maybe it is. I know I’m neither the first nor the last person to share their experience with this certification. Honestly, I don’t know if I’ll bring anything new to the table. But I figured I’d still share my take. If you’re interested, read on. If not, feel free to check out my other articles. This article will not tell you how to pass the certification.\nWhy I Took It Security+ wasn’t about learning everything from …","date":"2025-05-10","permalink":"/posts/how-i-passed-the-comptia-security+-certification/","summary":"This might sound like clickbait or just another post about Security+, and maybe it is. I know I’m neither the first nor the last person to share their experience with this certification. Honestly, I …","tags":null,"title":"How I Passed the CompTIA Security+ Certification"},{"content":"Upgrading from Red Hat Enterprise Linux (RHEL) 8 to RHEL 9 in an offline environment requires two main stages: first, upgrading to the latest RHEL 8 version (8.10), followed by upgrading from RHEL 8 to RHEL 9. This guide will walk you through the necessary steps for each part of the process, addressing potential issues along the way, and is specifically designed for an offline upgrade using local ISO images.\nThe ISO images required for this upgrade are:\nRHEL 8.10: rhel-8.10-x86_64-dvd.iso RHEL …","date":"2025-05-03","permalink":"/posts/offline-upgrade-from-rhel8-to-rhel9-using-an-iso/","summary":"Upgrading from Red Hat Enterprise Linux (RHEL) 8 to RHEL 9 in an offline environment requires two main stages: first, upgrading to the latest RHEL 8 version (8.10), followed by upgrading from RHEL 8 …","tags":null,"title":"Offline Upgrade From RHEL8 to RHEL9 using an ISO"},{"content":"Yesterday, I had a meeting with an international consulting firm about the Digital Operational Resilience Act (DORA), which officially comes into effect tomorrow on January 17, 2025. This new regulation will significantly impact banks worldwide that have branches in Europe. Among its many requirements, it introduces something that caught my attention: Threat-Led Penetration Testing (TLPT).\nBut what is TLPT, and who needs It? Simply put, TLPT is a type of red teaming . But when does it apply, and …","date":"2025-01-16","permalink":"/posts/doras-tlpt-mandate-is-your-bank-ready/","summary":"Yesterday, I had a meeting with an international consulting firm about the Digital Operational Resilience Act (DORA), which officially comes into effect tomorrow on January 17, 2025. This new …","tags":null,"title":"DORA's TLPT Mandate: Is Your Bank Ready?"},{"content":"Introduction Threat modeling can feel intimidating, especially if you\u0026amp;rsquo;re unsure where to begin, don’t know the right tools, or are unfamiliar with the methodologies. In this article, I want to present the concept and apply it to a real-world scenario to demonstrate its value.\nBut before we dive into the example, it\u0026amp;rsquo;s important to address some questions why threat modeling is essential and why it often gets neglected despite the benefits.\nThough it’s often linked with SSDLC and the …","date":"2024-12-30","permalink":"/posts/threat-modeling-hands-on/","summary":"Introduction Threat modeling can feel intimidating, especially if you\u0026amp;rsquo;re unsure where to begin, don’t know the right tools, or are unfamiliar with the methodologies. In this article, I want to …","tags":null,"title":"Threat Modeling Hands-On"},{"content":"While I explained in my previous article how to collect Windows Event Logs which already provide some valuable insights, it is fair to say that they often lack the depth needed for effective threat detection and analysis. This is why deploying Sysmon is the next step in advanced threat hunting.\nSysmon Overview Sysmon is both a Windows system service and a driver from Microsoft SysInternals that monitors and logs detailed system activity, such as process creation, network connections, and file …","date":"2024-12-26","permalink":"/posts/deploying-sysmon-via-gpo/","summary":"While I explained in my previous article how to collect Windows Event Logs which already provide some valuable insights, it is fair to say that they often lack the depth needed for effective threat …","tags":null,"title":"Deploying Sysmon via GPO"},{"content":"As a security engineer with some experience in GRC, even though it is not my primary focus in my day to day work, I believe that some cybersecurity frameworks knowledge helps security engineers take a step back and better prioritize their efforts. Today, I would like to present the NIST Cybersecurity Framework (CSF) 2.0 as one of the most widely used frameworks.\nWhether you’re new to the CSF or have been using it for years, this overview will walk you through what it encompasses, its recent …","date":"2024-11-15","permalink":"/posts/using-nist-csf-2-0-for-smes/","summary":"As a security engineer with some experience in GRC, even though it is not my primary focus in my day to day work, I believe that some cybersecurity frameworks knowledge helps security engineers take a …","tags":null,"title":"Using NIST CSF 2.0 for SMEs"},{"content":"Introduction Collecting Windows Event logs is crucial for maintaining a secure and well-monitored IT environment. Whether it’s tracking user logins, monitoring changes to critical systems, or detecting potential security threats, Windows event logs provide the detailed visibility you need to understand what\u0026amp;rsquo;s happening across your network—especially on critical machines like Domain Controllers (DCs). Without these logs, you’re basically flying blind when it comes to identifying issues or …","date":"2024-10-21","permalink":"/posts/siem-guide-to-windows-event-forwarding/","summary":"Introduction Collecting Windows Event logs is crucial for maintaining a secure and well-monitored IT environment. Whether it’s tracking user logins, monitoring changes to critical systems, or …","tags":null,"title":"SIEM - Guide to Windows Event Logs Auditing and Forwarding"},{"content":"Introduction Lately, I found myself called on an incident where a critical security application was running on a Red Hat Enterprise Linux (RHEL) server. The disk had become fully saturated, causing the application’s unavailability. This was a cool, refreshing session of Linux commands for disk and partition manipulation.\nThe / root partition was full, but the /home partition had plenty of unused space. In this scenario, I needed to reduce the size of the /home partition and reallocate some of …","date":"2024-10-06","permalink":"/posts/reclaiming-disk-space-on-root-volume-by-shrinking-home-in-rhel-with-xfs/","summary":"Introduction Lately, I found myself called on an incident where a critical security application was running on a Red Hat Enterprise Linux (RHEL) server. The disk had become fully saturated, causing …","tags":null,"title":"Reclaiming Disk Space on Root Volume by Shrinking Home in RHEL with XFS"},{"content":"It has been 3 months since I moved from the tech industry to the banking sector, and here is my take on Swiss private banking cloud security. This article condenses what I have learned so far about the various regulations that apply to the Swiss private banking sector and its challenges around data confidentiality. Transitioning from a software company, where the main risk was supply chain attack, to a private bank, where client data confidentiality is the main concern, has been an eye-opening …","date":"2024-08-18","permalink":"/posts/learning-about-cloud-security-for-swiss-private-banks/","summary":"It has been 3 months since I moved from the tech industry to the banking sector, and here is my take on Swiss private banking cloud security. This article condenses what I have learned so far about …","tags":null,"title":"Learning About Cloud Security for Swiss Private Banks"},{"content":"Introduction: Understanding MITRE ATT\u0026amp;amp;CK Navigator The MITRE ATT\u0026amp;amp;CK Navigator is a powerful tool that helps cyber security professionals visualize and navigate the extensive ATT\u0026amp;amp;CK matrices. It provides a customizable interface to map out and understand the tactics, techniques, and procedures (TTPs) used by threat actors, making it essential for threat profiling, defensive coverage analysis, and strategic planning. Users can create layers either interactively or programmatically and …","date":"2024-06-17","permalink":"/posts/mitre-attack-gap-assessment-analysis-and-threat-profiling/","summary":"Introduction: Understanding MITRE ATT\u0026amp;amp;CK Navigator The MITRE ATT\u0026amp;amp;CK Navigator is a powerful tool that helps cyber security professionals visualize and navigate the extensive ATT\u0026amp;amp;CK …","tags":null,"title":"MITRE ATT\u0026CK - Gap Assessment Analysis and Threat Profiling"},{"content":"When looking for Endpoint Privilege Management (EPM) solutions, there are not a lot of options out there. The main market players are CyberArk, BeyondTrust, Delinea (previously Thycotic) and the Microsoft Intune Endpoint Privilege Management. The best solution may differ based on the operating systems, organization size, industry, and whether the company has many developers needing admin access. These factors can also affect the implementation difficulty.\nWhat is an EPM software? An EPM software …","date":"2024-05-21","permalink":"/posts/mastering-cyberark-epm-your-implementation-guide/","summary":"When looking for Endpoint Privilege Management (EPM) solutions, there are not a lot of options out there. The main market players are CyberArk, BeyondTrust, Delinea (previously Thycotic) and the …","tags":null,"title":"Mastering CyberArk EPM: Implementation Guide"},{"content":"Transitioning from ISO27001 certification to SOC2 compliance is a natural progression for many organizations. Whether you\u0026amp;rsquo;ve already obtained ISO27001 or have it in your sights, SOC2 is likely on the horizon, being one of the most coveted certifications for demonstrating robust security controls. Chances are, your organization is already fielding inquiries from customers\u0026amp;rsquo; security compliance teams about SOC2 readiness. And if crafting comprehensive security policies poses a challenge …","date":"2024-05-08","permalink":"/posts/writing-security-policies-for-soc2/","summary":"Transitioning from ISO27001 certification to SOC2 compliance is a natural progression for many organizations. Whether you\u0026amp;rsquo;ve already obtained ISO27001 or have it in your sights, SOC2 is likely …","tags":null,"title":"Writing Security Policies for SOC2"},{"content":"Introducing the MacOS Security Compliance Project The MacOS Security Compliance Project (mSCP) is an open source framework for programmatically generating security guidance. This project contains security baselines of technical security controls such as CIS Benchmark, NIST-800-171, NIST-800-53, DISA STIG which can be adapted to the specific needs of any organization. The workflow is quite simple:\nWhere tailoring is used to select which rules to include in a benchmark, customizing is modifying …","date":"2024-05-08","permalink":"/posts/streamline-macos-security-compliance-with-jamf-compliance-editor/","summary":"Introducing the MacOS Security Compliance Project The MacOS Security Compliance Project (mSCP) is an open source framework for programmatically generating security guidance. This project contains …","tags":null,"title":"Streamline MacOS Security Compliance with JAMF Compliance Editor"},{"content":"Compliance as Code Compliance as Code (CaC) can be simply put as IT security compliance policies written as code. Systems configuration can be audited by these CaC policies to demonstrate your infrastructure\u0026amp;rsquo;s compliance against regulations and industry standards such as CIS Benchmarks, DISA STIG, PCI DSS, HIPAA, and more. Organizations can automate assessment, monitoring and remediation of these compliance controls on various systems with the Security Content Automation Protocol (SCAP) …","date":"2024-05-01","permalink":"/posts/automate-compliance-and-security-hardening-using-openscap-and-ubuntu-security-guide/","summary":"Compliance as Code Compliance as Code (CaC) can be simply put as IT security compliance policies written as code. Systems configuration can be audited by these CaC policies to demonstrate your …","tags":null,"title":"Automate Compliance and Security Hardening Using OpenSCAP and Ubuntu Security Guide"},{"content":"In today\u0026amp;rsquo;s competitive job market, a well-crafted resume is the key to getting that first interview. A resume isn\u0026amp;rsquo;t everything, but it\u0026amp;rsquo;s what gets you from the screening stage to the first interview with the recruiter. There are plenty of resume builders available online, however most of them are not free or just have a free trial period of 14 days, and today I want to prove that there are excellent free alternatives out there.\nReactive Resume / Rx Resume Reactive/Rx Resume is …","date":"2024-04-14","permalink":"/posts/how-to-build-a-good-resume-for-free/","summary":"In today\u0026amp;rsquo;s competitive job market, a well-crafted resume is the key to getting that first interview. A resume isn\u0026amp;rsquo;t everything, but it\u0026amp;rsquo;s what gets you from the screening stage to the …","tags":null,"title":"How to Build a Good Resume for Free"},{"content":"Containers are ubiquitous in modern production environments within Kubernetes clusters hosted on various cloud platforms such as AWS EKS, Azure AKS, or GCP GKE. By consequence securing Docker images is a necessity for all companies. Both customers and vendors must ensure that the images they use are free from vulnerabilities that could compromise their systems and their data or, respectively, tarnish their reputation if they ship vulnerable images. Nowadays, it\u0026amp;rsquo;s well known that there are …","date":"2024-03-24","permalink":"/posts/vulnerability-scanning-of-docker-images-vendors-customers/","summary":"Containers are ubiquitous in modern production environments within Kubernetes clusters hosted on various cloud platforms such as AWS EKS, Azure AKS, or GCP GKE. By consequence securing Docker images …","tags":null,"title":"Docker Image Scanning: Answering Customer Vulnerability Report from a Vendor Perspective"}]